Introduction
Installing Reflection for Secure IT
System Requirements
Install and Uninstall Reflection for Secure IT
Install and Uninstall Reflection PKI Services Manager
Upgrading from Reflection for Secure IT version 7.x
Automatic Migration of Reflection 6.x and F-Secure Settings
Uninstall Reflection for Secure IT
Installer Advanced Tab
Getting Started
Get Started with the Server Console
Start and Stop the Server
Getting Help
Understanding Secure Shell
General Server Configuration
Saving Server Settings
Restore Default Settings
Status Tab
General Pane
Change the Server Port
Network Pane
Network Binding Dialog Box
Data Protection
Data Encryption
Data Integrity
Federal Information Processing Standard (FIPS)
Encryption Pane
Key Exchange
Key Exchange Pane
Server Authentication
Public Key Authentication
Configure Public Key Host Authentication
Identity Tab
Generate Host Private Key Dialog Box
Export Public Key Dialog Box
Certificate Authentication Overview
Configure Certificate Server Authentication
Windows Certificate Store Dialog Box
Kerberos (GSSAPI) Authentication
Configure GSSAPI Server and Client Authentication
User Authentication
Authentication Pane
Password and Keyboard Interactive Authentication
Configure Password User Authentication
Configure Keyboard Interactive User Authentication
Password Pane
Public Key Authentication for Users
Configure Public Key User Authentication: Reflection for Secure IT Windows Clients
Configure Public Key User Authentication: Reflection for Secure IT UNIX Clients
Public Key Pane
Certificate Authentication for Users
Configure Certificate Authentication for Users
Certificates Pane
RSA SecurID Authentication
Configure SecurID Authentication
RSA SecurID Pane
RADIUS Authentication
Configure RADIUS Authentication
RADIUS Pane
RADIUS Server Dialog Box
GSSAPI (Kerberos) Authentication
Configure User Authentication using Windows Credentials
GSSAPI / Kerberos V5 Pane
Use Cached Passwords
Manage Cached Passwords
Password Cache Pane
Domain Access Pane
Secure File Transfer
File Transfer Overview
Specify the User Login Directory
Customize Directory Access for File Transfers
Control Upload and Download Access
Virtual Root Directory in Reflection for Secure IT
Smart Copy and Checkpoint Resume
SFTP Directories Pane
Accessible Directory Settings Dialog Box
Controlling Access
Access Control Settings
Using Allow and Deny Rules for Access Control
Controlling Access from Client Computers
Client Host Access Control Pane
Client Host Access Control Dialog Box
Controlling Access by Group
Group Access Control Pane
Group Access Control Dialog Box
Controlling Access by User
User Access Control Pane
User Access Control Dialog Box
Command Shell Access
Permissions Pane
Working with Subconfigurations
Subconfiguration Overview
Configure Client Host-Specific Settings
Client Host Configuration Pane
Client Host Configuration Dialog Box
Configure Group-Specific Settings
Group Configuration Pane
Group Configuration Dialog Box
Configure User-Specific Settings
User Configuration Pane
User Configuration Dialog Box
Revert settings to inherited values
Port Forwarding
Port Forwarding Overview
Disable Port Forwarding
Using a Server Cluster
Configure a Reflection for Secure IT Cluster
Configure Cluster Dialog Box
Troubleshooting
Logging
Use the Windows Event Viewer
Event Logging Pane
Enable Logging to a Text File
Debug Logging Pane
Custom Log Events Dialog Box
Managing System Resources
Troubleshooting Group Settings
Troubleshooting Reflection for Secure IT Help
Reference
Files Used by Reflection for Secure IT
Regular Expression Syntax
Table of Migrated Settings
Table of Migrated PKI Settings
Manual Host Key Migration
Pattern Strings in Directory Paths
Keyboard Access to Console Features
PKI Services Manager Command Reference (winpki and pkid)
PKI Services Manager Configuration File Reference (pkid_config)
PKI Services Manager Map File Reference (pki_mapfile)
Sample PKI Services Manager Mapping Rules
Sample Map File with RuleType Stanzas
PKI Services Manager Return Codes
rsshd Command Line Utility
ssh-keygen Command Line Utility
ssh-certtool Command Reference
Glossary of Terms
authentication
CA (certification authority)
cipher
CRL (Certificate Revocation List)
data integrity
digital certificate
digital signature
encryption
GSSAPI (Generic Security Services Application Program Interface)
hash
Kerberos
MAC (Message Authentication Code)
passphrase
PKCS
PKI Services Manager Configuration File <<shared>>
PKI Services Manager data folder <<Windows>>
PKI Services Manager Map File <<shared>>
port forwarding
public key/private key
Reflection for Secure IT configuration file
Reflection for Secure IT data folder
Reflection for Secure IT migration log file
regular expression
SCP1
SCP2
Secure Shell
SFTP
trust anchor
UTC (Universal Time, Coordinated)
Windows home folder
Windows user profile folder
Copyrights and Notices